Skip to content

Free cyber exposure audit

What does an attacker see of your business — without hacking anything?

A passive external exposure audit reveals what is already public about you: leaked credentials, a spoofable domain, exposed services.

Request my exposure audit

What is already known about you before the first attempt?

Before attacking, a cybercriminal gathers information. No door needs forcing: a large part of your exposure is already public.

So the question is not whether information is circulating, but which information — and what it makes possible against you.

That is exactly what this audit looks at: the same thing an attacker sees, from the outside, while there is still time to close it.

What the audit reveals about your exposure

  • Whether employee credentials appear in known data breaches.
  • Whether your domain can be spoofed to send fraudulent emails in your name.
  • Which services or interfaces are publicly visible.
  • Whether lookalike domains, close to yours, have been registered.

What your report contains

A clear report: a risk verdict, the concrete exposure, and a prioritised action plan. Sensitive information — passwords, secrets — is always redacted: you are shown the risk, never the data to reuse.

A passive, non-intrusive audit

This audit touches none of your systems: it looks only at what is already publicly accessible. It is carried out on your own assets, with your authorisation.

Request your free audit

Leave your email and the domain to audit: we will send your report as soon as it is ready.

Frequently asked questions

What security guarantees does this site claim?

No certification is claimed, and the Security page says so explicitly. It describes the mechanisms — encryption in transit and at rest, authentication and authorisation, server-side validation, HTTP headers — so that an organisation commissioning a project knows what to ask for and how to check it got it.

How do I report a security flaw?

The Security page ends with a section dedicated to reporting, giving the address to use. Describe what you observed and how to reproduce it; do not exploit the flaw beyond what is needed to demonstrate it.

Who owns the code and the accounts created for a project?

That is a clause to write explicitly into the quote, never to leave implicit — and it covers two distinct things: ownership of the code produced, and who holds the hosting, domain name and third-party service accounts. The first without the second does not let you take over.